CVE-2022-4106
Wholesale Market for WooCommerce < 1.0.7 - Unauthenticated Arbitrary File Download
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The Wholesale Market for WooCommerce WordPress plugin before 1.0.7 does not have authorisation check, as well as does not validate user input used to generate system path, allowing unauthenticated attackers to download arbitrary file from the server.
El complemento de WordPress Wholesale Market para WooCommerce anterior a 1.0.7 no tiene verificación de autorización y tampoco valida la entrada del usuario utilizada para generar la ruta del sistema, lo que permite a atacantes no autenticados descargar archivos arbitrarios desde el servidor.
The Wholesale Market for WooCommerce plugin for WordPress is vulnerable to arbitrary file download due to missing capability checks and user input validation during the system path generation process in versions up to, and including, 1.0.6. This makes it possible for unauthenticated attackers to download arbitrary files on the affected sites server, including database configuration files. While version 1.0.7 adds capability checks, the issue remains exploitable by high-level users.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-11-21 CVE Reserved
- 2022-11-28 CVE Published
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
- CWE-552: Files or Directories Accessible to External Parties
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://wpscan.com/vulnerability/b60a0d3d-148f-4e9b-baee-7332890804ed | 2024-08-03 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cedcommerce Search vendor "Cedcommerce" | Wholesale Market For Woocommerce Search vendor "Cedcommerce" for product "Wholesale Market For Woocommerce" | < 1.0.7 Search vendor "Cedcommerce" for product "Wholesale Market For Woocommerce" and version " < 1.0.7" | wordpress |
Affected
|